CVE-2026-30075
Last modified
CVE-2026-30075 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. OpenAirInterface Version 2.2.0 has a Buffer Overflow vulnerability in processing UplinkNASTransport containing Authentication Response containing a NAS PDU with oversize response (For example 100 byte). The response is decoded by AMF and passed to the AUSF component for verification. EPSS estimates a 0.38% chance of exploitation in the next 30 days.
Description
OpenAirInterface Version 2.2.0 has a Buffer Overflow vulnerability in processing UplinkNASTransport containing Authentication Response containing a NAS PDU with oversize response (For example 100 byte). The response is decoded by AMF and passed to the AUSF component for verification. AUSF crashes on receiving this oversize response. This can prohibit users from further registration and verification and can cause Denial of Services (DoS).
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Openairinterface | Oai-Cn5g-Amf | 2.2.0 |
References
- https://gitlab.eurecom.fr/oai/cn5g/oai-cn5g-ausf/-/issues/6Exploit, Issue Tracking, Third Party Advisory
- https://gitlab.eurecom.fr/oai/cn5g/oai-cn5g-ausf/-/issues?show=eyJpaWQiOiI2IiwiZnVsbF9wYXRoIjoib2FpL2NuNWcvb2FpLWNuNWctYXVzZiIsImlkIjo1NDE5fQ%3D%3DExploit, Issue Tracking, Third Party Advisory
- https://gitlab.eurecom.fr/oai/cn5g/oai-cn5g-ausf/-/issues?show=eyJpaWQiOiI2IiwiZnVsbF9wYXRoIjoib2FpL2NuNWcvb2FpLWNuNWctYXVzZiIsImlkIjo1NDE5fQ%3D%3DExploit, Issue Tracking, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-30075?
How severe is CVE-2026-30075?
How do I fix CVE-2026-30075?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-30069A NULL pointer dereference in the UDMC registration handler …7.5
- CVE-2026-3007Successful exploitation of the stored cross-site scripting (…5.4
- CVE-2026-30070An issue in the HandleGetSharedData function of free5gc v4.0…7.5
- CVE-2026-30071An issue in the RechargePut function of free5gc v4.0.1 allow…7.5
- CVE-2026-30072A NULL pointer dereference in the CDR processing path of fre…7.5
- CVE-2026-30073An issue in the NssaiAvailabilitySubscriptionCreate componen…7.5
- CVE-2026-30077OpenAirInterface V2.2.0 AMF crashes when it fails to decode …7.5
- CVE-2026-30078OpenAirInterface V2.2.0 AMF crashes when it receives an NGAP…7.5
- CVE-2026-30079In OpenAirInterface V2.2.0 AMF, Out of sequence messages cau…9.8
- CVE-2026-3008Successful exploitation of the string injection vulnerabilit…6.6
- CVE-2026-30080OpenAirInterface v2.2.0 accepts Security Mode Complete witho…7.5
- CVE-2026-30082Multiple stored cross-site scripting (XSS) vulnerabilities i…6.1
Are you affected by CVE-2026-30075?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
